Red Hat Bugzilla – Bug 1607329
CVE-2018-14367 wireshark: CoAP dissector infinite loop (wnpa-sec-2018-42)
Last modified: 2018-08-07 15:01:39 EDT
It was found that CoAP dissector could crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. Upstream bug(s): https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14966 External References: https://www.wireshark.org/security/wnpa-sec-2018-42.html
Created wireshark tracking bugs for this issue: Affects: fedora-all [bug 1607334]
The wireshark shipped in Red Hat Enterprise Linux 6 and 7 do not have the "Allocate information for upper layers" functionality implementation in the dissect_coap function (epan/dissectors/packet-coap.c file).
Statement: This issue did not affect the versions of wireshark as shipped with Red Hat Enterprise Linux 6 and 7 (versions 1.8.10 and 1.10.14, respectively).